People walk past a Capital One Bank branch in Los Angeles, California. A hacker accessed more than 100 million credit card applications with US financial heavyweight Capital One, the firm said on July 29, 2019, in one of the biggest data thefts to hit a financial services company. AFP
People walk past a Capital One Bank branch in Los Angeles, California. A hacker accessed more than 100 million credit card applications with US financial heavyweight Capital One, the firm said on July 29, 2019, in one of the biggest data thefts to hit a financial services company. AFP
People walk past a Capital One Bank branch in Los Angeles, California. A hacker accessed more than 100 million credit card applications with US financial heavyweight Capital One, the firm said on July 29, 2019, in one of the biggest data thefts to hit a financial services company. AFP
People walk past a Capital One Bank branch in Los Angeles, California. A hacker accessed more than 100 million credit card applications with US financial heavyweight Capital One, the firm said on July

All you need to know about the Capital One data breach


  • English
  • Arabic

One of the US's biggest credit card issuers, Capital One Financial, is the latest big business to be hit by a data breach, disclosing that roughly 100 million people had some personal information stolen by a hacker.

The alleged hacker, Paige A Thompson, obtained Social Security and bank account numbers in some instances, as well other information such as names, birth dates, credit scores and self-reported income, the bank said late last month. It said no credit card account numbers or log-in credentials were compromised.

Capital One Financial is just the latest business to suffer a data breach. Only last week Equifax, the credit reporting company, announced a $700 (Dh2.6bn)  million settlement over its own 2017 data breach that impacted half of the US population. Other companies in the US that have had breaches include the hotel chain Marriott, retail giants Home Depot and Target.

What happened at Capital One?

Ms Thompson, 33, who uses the online handle "erratic," allegedly obtained access to Capital One data stored on Amazon's cloud computing platform Amazon Web Services in March. She downloaded the data and stored it on her own servers, according to the complaint.

Ms Thompson was a systems engineer at Amazon Web Services between 2015 and 2016, about three years before the breach took place. The breach went unnoticed by Amazon and Capital One.

Vehicles are parked outside the home of Paige A Thompson, who uses the online handle 'erratic'. Ms Thompson was arrested late last month and has been charged with a single count of computer fraud and abuse in US District Court in Seattle. AP
Vehicles are parked outside the home of Paige A Thompson, who uses the online handle 'erratic'. Ms Thompson was arrested late last month and has been charged with a single count of computer fraud and abuse in US District Court in Seattle. AP

Ms Thompson used the anonymous web browser Tor and a Virtual Private Network in extracting the data — typical methods hackers use to try to mask infiltrations — but she later boasted about the hack on Twitter and a chat group on Slack, posting screenshots as evidence of her exploit.

It was only after Ms Thompson began bragging about her feat in a private group chat with other hackers that someone reached out to Capital One to let them know on July 17.

Once the informant told Capital One the company closed the vulnerability. The company verified its information had been stolen by July 19 and started tracking Ms Thompson and working with the FBI. The FBI raided her residence on Monday and seized digital devices. An initial search turned up files that referenced Capital One and "other entities that may have been targets of attempted or actual network intrusions."

What data the hacker access?

The data breach involves about 100 million people in the US and 6 million in Canada.

In this security camera video provided by a neighbour, federal agents conduct a raid on the home of Paige A Thompson in Seattle. Ms Thompson is accused of accessing the personal information of millions of Capital One credit card holders or credit card applicants in the US and Canada. AP
In this security camera video provided by a neighbour, federal agents conduct a raid on the home of Paige A Thompson in Seattle. Ms Thompson is accused of accessing the personal information of millions of Capital One credit card holders or credit card applicants in the US and Canada. AP

Prosecutors said a misconfigured Capital One firewall let Ms Thompson access folders of data that Amazon Web Services was hosting for the bank. Ms Thompson sent a command that returned a list of more than 700 folders and copied data from an unspecified number of them. Capital One said the bulk of the hacked data consisted of information supplied by consumers and small businesses who applied for credit cards between 2005 and early 2019. The hacker also was able to gain some access to fragments of transactional information from dates in 2016, 2017 and 2018.

The bank said it believes it is unlikely that the information obtained was used for fraud, but the investigation is ongoing.

Capital One says 140,000 individuals had their Social Security numbers accessed, and another 80,000 had their bank account information accessed.

How did Capital One handle the breach?

Capital One says once it learned of the breach on July 17, it immediately closed the vulnerability, and it was able to figure out what Ms Thompson accessed 36 hours later, on July 19. The company was able to build a profile on Ms Thompson from their internal investigation, and handed that to the FBI, who arrested her 10 days later, the day the bank disclosed the breach.

By contrast, it took Equifax six weeks before it publicly disclose its security incident, which was similar in size.

What about those affected by the breach? 

Capital One said it will reach out to those affected using "a variety of channels."

That bank said it will make free credit monitoring and identity protection available to everyone affected. The company also said that consumers can visit www.capitalone.com/facts2019 for more information. In Canada, information can be found at www.capitalone.ca/facts2019 .

Consumers should also obtain copies of their credit reports at AnnualCreditReport.com. By US federal law, consumers can receive a free copy of their credit report every 12 months from each of the three big agencies — Equifax, Experian and TransUnion.

What steps should I take if I think I am affected?

Look over all of your listed accounts and loans to make sure that all of your personal information is correct and that you authorised the transaction. If you find something suspicious, contact the company that issued the account and the credit-rating agency.

You may also want to consider freezing your credit, which stops thieves from opening new credit cards or loans in your name. This can be done online. Consumers can freeze their credit for free because of a law that President Donald Trump signed last year. Before that, fees were typically $5 to $10 per rating agency.

You'll need to remember to temporarily unfreeze your credit if you apply for a new credit card or loan. Also keep in mind that a credit freeze won't protect you from thieves who file a fraudulent tax return in your name or make charges against an existing account.

You should also change your passwords regularly. CreditCards.com industry analyst Ted Rossman recommends using a password aggregator like LastPass that helps create strong, unique passwords for all of your logins.

GIANT REVIEW

Starring: Amir El-Masry, Pierce Brosnan

Director: Athale

Rating: 4/5

Who's who in Yemen conflict

Houthis: Iran-backed rebels who occupy Sanaa and run unrecognised government

Yemeni government: Exiled government in Aden led by eight-member Presidential Leadership Council

Southern Transitional Council: Faction in Yemeni government that seeks autonomy for the south

Habrish 'rebels': Tribal-backed forces feuding with STC over control of oil in government territory

Fifa%20World%20Cup%20Qatar%202022%20
%3Cp%3E%3Cstrong%3EFirst%20match%3A%20%3C%2Fstrong%3ENovember%2020%0D%3Cbr%3E%3Cstrong%3EFinal%2016%20round%3A%20%3C%2Fstrong%3EDecember%203%20to%206%0D%3Cbr%3E%3Cstrong%3EQuarter-finals%3A%20%3C%2Fstrong%3EDecember%209%20and%2010%0D%3Cbr%3E%3Cstrong%3ESemi-finals%3A%20%3C%2Fstrong%3EDecember%2013%20and%2014%0D%3Cbr%3E%3Cstrong%3EFinal%3A%20%3C%2Fstrong%3EDecember%2018%3C%2Fp%3E%0A
UAE currency: the story behind the money in your pockets
RESULT

Al Hilal 4 Persepolis 0
Khribin (31', 54', 89'), Al Shahrani 40'
Red card: Otayf (Al Hilal, 49')

Sly%20Cooper%20and%20the%20Thievius%20Raccoonus
%3Cp%3E%3Cstrong%3EDeveloper%3A%3C%2Fstrong%3E%20Sucker%20Punch%20Productions%3Cbr%3E%3Cstrong%3EPublisher%3A%3C%2Fstrong%3E%20Sony%20Computer%20Entertainment%3Cbr%3E%3Cstrong%3EConsole%3A%3C%2Fstrong%3E%20PlayStation%202%20to%205%3Cbr%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%205%2F5%3C%2Fp%3E%0A
UAE currency: the story behind the money in your pockets
Turning%20waste%20into%20fuel
%3Cp%3EAverage%20amount%20of%20biofuel%20produced%20at%20DIC%20factory%20every%20month%3A%20%3Cstrong%3EApproximately%20106%2C000%20litres%3C%2Fstrong%3E%3C%2Fp%3E%0A%3Cp%3EAmount%20of%20biofuel%20produced%20from%201%20litre%20of%20used%20cooking%20oil%3A%20%3Cstrong%3E920ml%20(92%25)%3C%2Fstrong%3E%3C%2Fp%3E%0A%3Cp%3ETime%20required%20for%20one%20full%20cycle%20of%20production%20from%20used%20cooking%20oil%20to%20biofuel%3A%20%3Cstrong%3EOne%20day%3C%2Fstrong%3E%3C%2Fp%3E%0A%3Cp%3EEnergy%20requirements%20for%20one%20cycle%20of%20production%20from%201%2C000%20litres%20of%20used%20cooking%20oil%3A%3Cbr%3E%3Cstrong%3E%E2%96%AA%20Electricity%20-%201.1904%20units%3Cbr%3E%E2%96%AA%20Water-%2031%20litres%3Cbr%3E%E2%96%AA%20Diesel%20%E2%80%93%2026.275%20litres%3C%2Fstrong%3E%3C%2Fp%3E%0A
%20Ramez%20Gab%20Min%20El%20Akher
%3Cp%3E%3Cstrong%3ECreator%3A%3C%2Fstrong%3E%20Ramez%20Galal%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStarring%3A%3C%2Fstrong%3E%20Ramez%20Galal%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStreaming%20on%3A%20%3C%2Fstrong%3EMBC%20Shahid%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%20%3C%2Fstrong%3E2.5%2F5%3C%2Fp%3E%0A
Our legal columnist

Name: Yousef Al Bahar

Advocate at Al Bahar & Associate Advocates and Legal Consultants, established in 1994

Education: Mr Al Bahar was born in 1979 and graduated in 2008 from the Judicial Institute. He took after his father, who was one of the first Emirati lawyers

The specs: 2018 Nissan Altima


Price, base / as tested: Dh78,000 / Dh97,650

Engine: 2.5-litre in-line four-cylinder

Power: 182hp @ 6,000rpm

Torque: 244Nm @ 4,000rpm

Transmission: Continuously variable tranmission

Fuel consumption, combined: 7.6L / 100km

If you go

The flights

There are direct flights from Dubai to Sofia with FlyDubai (www.flydubai.com) and Wizz Air (www.wizzair.com), from Dh1,164 and Dh822 return including taxes, respectively.

The trip

Plovdiv is 150km from Sofia, with an hourly bus service taking around 2 hours and costing $16 (Dh58). The Rhodopes can be reached from Sofia in between 2-4hours.

The trip was organised by Bulguides (www.bulguides.com), which organises guided trips throughout Bulgaria. Guiding, accommodation, food and transfers from Plovdiv to the mountains and back costs around 170 USD for a four-day, three-night trip.

 

The specs
Engine: 2.7-litre 4-cylinder Turbomax
Power: 310hp
Torque: 583Nm
Transmission: 8-speed automatic
Price: From Dh192,500
On sale: Now
Company%C2%A0profile
%3Cp%3E%3Cstrong%3EName%3A%20%3C%2Fstrong%3EPyppl%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EEstablished%3A%20%3C%2Fstrong%3E2017%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EFounders%3A%20%3C%2Fstrong%3EAntti%20Arponen%20and%20Phil%20Reynolds%26nbsp%3B%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EBased%3A%3C%2Fstrong%3E%20UAE%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ESector%3A%3C%2Fstrong%3E%20financial%20services%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EInvestment%3A%3C%2Fstrong%3E%20%2418.5%20million%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EEmployees%3A%3C%2Fstrong%3E%20150%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EFunding%20stage%3A%3C%2Fstrong%3E%20series%20A%2C%20closed%20in%202021%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EInvestors%3A%3C%2Fstrong%3E%20venture%20capital%20companies%2C%20international%20funds%2C%20family%20offices%2C%20high-net-worth%20individuals%3C%2Fp%3E%0A
The specs

Engine: 2.0-litre 4cyl turbo

Power: 261hp at 5,500rpm

Torque: 405Nm at 1,750-3,500rpm

Transmission: 9-speed auto

Fuel consumption: 6.9L/100km

On sale: Now

Price: From Dh117,059

Director: Laxman Utekar

Cast: Vicky Kaushal, Akshaye Khanna, Diana Penty, Vineet Kumar Singh, Rashmika Mandanna

Rating: 1/5

UAE currency: the story behind the money in your pockets